MalwareRansomwareData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICFINANCIAL_ACCOUNTLowContained
STURM, RUGER & COMPANY, INC.
bd_38f04b97485bb418 · schema v1 · pii pii-v1
Full breach record for STURM, RUGER & COMPANY, INC. →Sturm, Ruger & Company, Inc. disclosed a data breach involving its third-party payment processor, Freestyle Solutions. Malware on Freestyle's server captured customer payment card information and PII from ShopRuger.com between September 18, 2020, and February 3, 2022. Sturm, Ruger engaged Verizon for forensic investigation, notified law enforcement, and offered 12 months of identity theft protection to affected individuals.
California clockDiscovered Aug 2, 2022 → Notified Aug 18, 202216d ✓ CA 60-day OK15 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_9393cab4cdd552b6Maine State AGfiled 2022-08-17Verified
- bd_ebaf2f767137b90aOregon State AGfiled 2022-08-17Verified
- bd_ab208d75cc9435eaWashington State AGfiled 2022-08-18(1d gap)Verified
- bd_424fddae62906520New Hampshire State AGfiled 2022-08-19(2d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 15d gap
- bd_33d8926df2b3726eDelaware State AGfiled 2022-08-02(15d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-556349
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 17, 2022
- Raw hash
- 6b86c83b14635db857c0dd347dfe2689cc6b0c57c78625f52189abb1fd34dbdb
Reporting entity
- Name
- STURM, RUGER & COMPANY, INC.norm: sturm ruger
Victim entity
- Name
- STURM, RUGER & COMPANY, INC.norm: sturm ruger
Incident
- Discovered
- Aug 2, 2022
- Materiality determined
- —
- Notification sent
- Aug 18, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified certain regulatory authorities in accordance with applicable law
- Third party
- via Freestyle Solutions
- Initial access
- supply_chain
Compliance
- Time to disclose
- 15 days(15 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 16d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 2, 2022→ Notified: Aug 18, 202216d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.